Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms

Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit Platforms
复制标题

DOI:
10.1145/2976749.2978403
复制
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Christian Wressnegger;Fabian Yamaguchi;Alwin Maier;Konrad Rieck
Christian Wressnegger;Fabian Yamaguchi;Alwin Maier;Konrad Rieck
中科院分区:
其他
文献类型:
--
作者:
Christian Wressnegger;Fabian Yamaguchi;Alwin Maier;Konrad Rieck

文献摘要

相似文献

整数计算中的细微缺陷是系统代码中可利用漏洞的主要来源。不幸的是,即使在一个平台上显示为安全的代码在另一个平台上也可能是脆弱的,这使得代码的迁移成为一个显著的安全挑战。在本文中,我们首次研究了在32位平台上按预期工作的代码如何在64位平台上变得脆弱。为此,我们系统地回顾了平台之间数据模型变化的影响。我们发现整数类型的更大宽度和可寻址内存的增加引入了以前不存在的漏洞,这些漏洞通常潜伏在程序代码中。我们根据经验评估了Debian stable(“杰西”)源代码和GitHub上托管的200个流行开源项目中这些缺陷的普遍性。此外,我们还讨论了在我们的研究中发现的64位迁移漏洞,包括Chromium、Boost C++库、libarchive、Linux内核和zlib中的漏洞。
Subtle flaws in integer computations are a prime source for exploitable vulnerabilities in system code. Unfortunately, even code shown to be secure on one platform can be vulnerable on another, making the migration of code a notable security challenge. In this paper, we provide the first study on how code that works as expected on 32-bit platforms can become vulnerable on 64-bit platforms. To this end, we systematically review the effects of data model changes between platforms. We find that the larger width of integer types and the increased amount of addressable memory introduce previously non-existent vulnerabilities that often lie dormant in program code. We empirically evaluate the prevalence of these flaws on the source code of Debian stable ("Jessie") and 200 popular open-source projects hosted on GitHub. Moreover, we discuss 64-bit migration vulnerabilities that have been discovered as part of our study, including vulnerabilities in Chromium, the Boost C++ Libraries, libarchive, the Linux Kernel, and zlib.